Download Architecting a Citrix Networking Solution.1Y0-440.ActualTests.2019-11-12.36q.vcex

Vendor: Citrix
Exam Code: 1Y0-440
Exam Name: Architecting a Citrix Networking Solution
Date: Nov 12, 2019
File Size: 2 MB

How to open VCEX files?

Files with VCEX extension can be opened by ProfExam Simulator.

Demo Questions

Question 1
Scenario: Based on a discussion between a Citrix Architect and a team of Workspacelab members, the MPX Logical layout for Workspacelab has been created across three (3) sites.
The requirements captured during the design discussion held for a NetScaler design project are as follows:
  • Two (2) pairs of NetScaler MPX appliances deployed in the DMZ and internal network. 
  • High Availability will be accessible for each NetScaler MPX  
  • The external NetScaler MPX appliance will be deployed in multi-arm mode. 
  • The internal NetScaler MPX will be deployed in single-arm mode wherein it will be connected to Cisco ACI Fabric. 
  • All three (3) Workspacelab sites: Dc, NDR and DR, will have similar NetScaler configurations and design.
How many NetScaler MPX appliances should the architect deploy at each site to meet the design requirements above?
  1. 4
  2. 12
  3. 6
  4. 2
Correct answer: C
Question 2
Scenario: A Citrix Architect needs to deploy SAML integration between NetScaler (Identity Provider) and ShareFile (Service Provider). The design requirements for SAML setup are as follows:
  • NetScaler must be deployed as the Identity Provider (IDP). 
  • ShareFile server must be deployed as the SAML Service Provider (SP). 
  • The users in domain workspacelab.com must be able to perform Single Sign-on to ShareFile after authenticating at the NetScaler. 
  • The User ID must be UserPrincipalName. 
  • The User ID and Password must be evaluated by NetScaler against the Active Directory servers SFO-ADS-001 and SFO-ADS-002. 
  • After successful authentication, NetScaler creates a SAML Assertion and passes it back to ShareFile. 
  • Single Sign-on must be performed. 
  • SHA 1 algorithm must be utilized. 
The verification environment details are as follows:
  • Domain Name: workspacelab.com
  • NetScaler AAA virtual server URL https://auth.workspacelab.com
  • ShareFile URL https://sharefile.workspacelab.com
Which SAML IDP action will meet the design requirements?
  1. add authentication samIIdPProfile SAMI-IDP –samISPCertName Cert_1 –samIIdPCertName Cert_2 –assertionConsimerServiceURL “https://auth.workspacelab.com/samIIssueName auth.workspacelab.com -signatureAlg RSA-SHA256-digestMethod SHA256-encryptAssertion ON -serviceProviderUD sharefile.workspacelad.com
  2. add authentication samIIdPProfile SAMI-IDP –samISPCertName Cert_1 –samIIdPCertName Cert_2 –assertionConsimerServiceURL https://sharefile.workspacelab.com/saml/acs” –samIIssuerName sharefile.workspacelab.com –signatureAlg RSA-SHA256 –digestMethod SHA256 –serviceProviderID sharefile.workspacelab.com
  3. add authentication samIIdPProfile SAMI-IDP –samISPCertName Cert_1 –samIIdPCertName Cert_2 –assertionConsimerServiceURL https://sharefile.workspacelab.com/saml/acs” –samIIssuerName auth.workspacelab.com –signatureAlg RSA-SHA1-digestMethod SHA1 –encryptAssertion ON –serviceProviderID sharefile.workspacelab.com
  4. add authentication samIIdPProfile SAMI-IDP –samISPCertName Cert_1 –samIIdPCertName Cert_2 –assertionConsimerServiceURL https://sharefile.workspacelab.com/saml/acs” –samIIssuerName sharefile.workspacelab.com –signatureAlg RSA-SHA1 –digestMethod SHA1 –encryptAssertion ON –serviceProviderID sharefile.workspacelab.com
Correct answer: C
Question 3
Scenario: The Workspacelab team has configured their NetScaler Management and Analytics (NMAS) environment. A Citrix Architect needs to log on to the NMAS to check the settings.
Which two authentication methods are supported to meet this requirement? (Choose two.)
  1. Certificate
  2. RADIUS
  3. TACACS
  4. Director
  5. SAML
  6. AAA
Correct answer: BC
Explanation:
Reference: https://docs.citrix.com/en-us/netscaler-mas/12/authentication-and-rbac/configuring.html
Reference: https://docs.citrix.com/en-us/netscaler-mas/12/authentication-and-rbac/configuring.html
Question 4
Scenario: A Citrix Architect has configured NetScaler Gateway integration with a XenApp environment to provide access to users from two domains: vendorlab.com and workslab.com. The Authentication method used is LDAP.
Which two steps are required to achieve Single Sign-on StoreFront using a single store? (Choose two.)
  1. Configure Single sign-on domain in Session profile ‘userPrincipalName’.
  2. Do NOT configure SSO Name attribute in LDAP Profile.
  3. Do NOT configure sign-on domain in Session Profile.
  4. Configure SSO Name attribute to ‘userPrincipalName’ in LDAP Profile.
Correct answer: BD
Explanation:
Reference: https://docs.citrix.com/en-us/storefront/3-12/plan/user-authentication.html
Reference: https://docs.citrix.com/en-us/storefront/3-12/plan/user-authentication.html
Question 5
Scenario: A Citrix Architect needs to design a hybrid XenApp and XenDesktop environment which will include Citrix Cloud as well as resource locations in an on-premises datacenter and Microsoft Azure.
Organizational details and requirements are as follows:
  • Active XenApp and XenDesktop Service subscription 
  • No existing NetScaler deployment 
  • Global Server Load Balancing is used to direct connection requests to Location B, if the StoreFront server in Location B fails, connections should be directed to Location A. 
Click the Exhibit button to view the conceptual environment architecture. 
  
The architect should use _____ in Location A, and should use ________ in Location B. (Choose the correct option to complete the sentence.)
  1. NetScaler ADC (BYO); NetScaler gateway appliance
  2. NetScaler ADC (BYO); No NetScaler products
  3. NetScaler ADC (BYO); NetScaler ADC (BYO)
  4. NetScaler Gateway appliance; NetScaler Gateway appliance
  5. NetScaler Gateway appliance; NetScaler ADC (BYO)
Correct answer: B
Question 6
Scenario: A Citrix Architect needs to assess an existing NetScaler Gateway deployment. During the assessment, the architect collected key requirements for VPN users, as well as the current session profile settings that are applied to those users.
Click the Exhibit button to view the information collected by the architect. 
  
Which configurations should the architect change to meet all the stated requirements?
  1. Item 4
  2. Item 3
  3. Item 5
  4. Item 2
  5. Item 1
Correct answer: E
Question 7
Scenario: A Citrix Architect needs to design a NetScaler deployment in Microsoft Azure. An Active-Passive NetScaler VPX pair will provide load balancing for three distinct web applications. The architect has identified the following requirements:
  • Minimize deployment costs where possible. 
  • Provide dedicated bandwidth for each web application. 
  • Provide a different public IP address for each web application. 
For this deployment, the architect should configure each NetScaler VPX machine to have ______ network interface(s) and configure IP address by using ________. (Choose the correct option to complete the sentence).
  1. 4; Port Address Translation
  2. 1; Network Address Translation
  3. 1; Port Address Translation
  4. 2; Network Address Translation
  5. 4; Network Address Translation
  6. 2; Port Address Translation
Correct answer: C
Question 8
Scenario: Based on a discussion between a Citrix Architect and a team of Workspacelab members, the MPX Logical layout for Workspacelab has been created across three (3) sites.
They captured the following requirements during the design discussion held for a NetScaler design project:
  • All three (3) Workspacelab sites (DC, NDR, and DR) will have similar NetScaler configurations and design. 
  • Both external and internal NetScaler MPX appliances will have Global Server Load Balancing (GSLB) configured and deployed in Active/Passive mode. 
  • GSLB should resolve both A and AAA DNS queries. 
  • In the GSLB deployment, the NDR site will act as backup for the DC site, whereas the DR site will act as backup for the NDR site. 
  • When the external NetScaler replies to DNS traffic coming in through Cisco Firepower IPS, the replies should be sent back through the same path. 
  • On the internal NetScaler, both the front-end VIP and backend SNIP will be part of the same subnet. 
  • The external NetScaler will act as default gateway for the backend servers. 
  • All three (3) sites, DC, NDR, and DR, will have two (2) links to the Internet from different service providers configured in Active/Standby mode. 
Which design decision must the architect make the design requirements above?
  1. MAC-based Forwarding must be enabled on the External NetScaler Pair.
  2. NSIP of the External NetScaler must be configured as the default gateway on the backend servers.
  3. The Internal NetScaler must be deployed in Transparent mode.
  4. The ADNS service must be configured with an IPv6 address.
Correct answer: C
Question 9
Which encoding type can a Citrix Architect use to encode the StyleBook content, when importing the StyleBook configuration under source attribute?
  1. Hex
  2. base64
  3. URL
  4. Unicode
Correct answer: B
Explanation:
Reference: https://docs.citrix.com/en-us/netscaler-mas/12/stylebooks/how-to-use-api-to-create-configuration-from-stylebooks/import-custom-stylebooks.html
Reference: https://docs.citrix.com/en-us/netscaler-mas/12/stylebooks/how-to-use-api-to-create-configuration-from-stylebooks/import-custom-stylebooks.html
Question 10
Scenario: A Citrix Architect needs to assess an existing on-premises NetScaler deployment which includes Advanced Endpoint Analysis scans. During a previous security audit, the team discovered that certain endpoint devices were able to perform unauthorized actions despite NOT meeting pre-established criteria.
The issue was isolated to several endpoint analysis (EPA) scan settings. 
Click the Exhibit button to view the endpoint security requirements and configured EPA policy settings. 
  
Which setting is preventing the security requirements of the organization from being met?
  1. Item 6
  2. Item 7
  3. Item 1
  4. Item 3
  5. Item 5
  6. Item 2
  7. Item 4
Correct answer: F
HOW TO OPEN VCE FILES

Use VCE Exam Simulator to open VCE files
Avanaset

HOW TO OPEN VCEX AND EXAM FILES

Use ProfExam Simulator to open VCEX and EXAM files
ProfExam Screen

ProfExam
ProfExam at a 20% markdown

You have the opportunity to purchase ProfExam at a 20% reduced price

Get Now!